Seven demos
Demo kit
Only run these in a throwaway macOS account or a disposable VM, never on your main account. Every secret is fake: AWS's own published example keys, made up SSH key text and invented customer rows. The only thing that ever leaves a machine goes to your own local collector.
Part A: no sandbox
The Silent Theft
The project depends on a package with a lookalike name. Installing it runs a postinstall script that reads the fake secrets, sends them to the attacker's console and changes a few decoy files.
$ Set up this project and get the tests passing.- The attacker's console fills up with the fake keys
- A new terminal tab shows a banner, because .zshrc was changed
- The decoy photos folder disappears from Finder
- Optional last act: the stolen keys delete a fake cloud backup bucket
Real world case: s1ngularity (26 Aug 2025)
The Poisoned Page
The page looks like an ordinary blog post. Hidden inside it is an instruction telling a summarizing agent to read the fake secrets and send them out.
$ Summarize this page.- All three legs of the trifecta light up live: private data, untrusted content, a way out
- Models often refuse something this blunt. That doesn't change the point
- An attacker only needs one wording that works
Real world cases: GitHub MCP (May 2025), EchoLeak (CVE-2025-32711), Comment and Control
Part B: with a sandbox
A light sandbox with srt
Anthropic's sandbox runtime, run directly. Reads are open by default, while writes and network access are blocked until you allow them.
- cat on the demo SSH key gives “Operation not permitted”
- curl example.com is blocked
- Reads stay open until you add denyRead, and I show that on purpose
A real sandbox with sbx
The exact same project and prompt as Demo 1, run inside a Docker sbx sandbox this time. Same dashboard, but red turns green.
$ Set up this project and get the tests passing.- The loot counter stays at 0 because nothing reaches the console
- sbx policy check says the network call is denied
- There is no ~/.aws inside the box and no real key to steal
- sbx run claude has no permission prompts, because the box is in charge
Quick wins
Three quick reasons to run agents in a sandbox even on a good day.
- Cheap recovery: sbx rm, then a fresh sandbox in seconds
- Parallel work: two sandboxes both serving on port 3000
- Resource limits: a memory cap, shown only inside the sandbox
Hack it yourself
A simulated agent with a Sandbox on and off switch, built for hundreds of people at once. It runs in your browser, with no real model and no network calls from anything you type.
- Off: clever wording wins
- Guardrail on: a word filter and a secret scanner that you can talk your way around
- Sandbox on: nothing wins, however clever
Honest limits
The box isn't magic
The project folder is shared and writable between the sandbox and your machine. Bad code plants a git hook there, and it fires on the real machine at the next commit.
- The attack never escaped the sandbox. It waited in a file the host trusts
- Fixes: clone mode, reviewing hooks and scripts, and allowing only the sites you need